Electronic Locks for Enterprise Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access-control solutions for data storage systems in IT networks are inadequate, allowing unauthorized technicians to remove hardware components, leading to service interruptions and data loss, and physical keys can be copied or misused in shared data centers.
Innovation Solution
A security system that employs electronic locks and a security controller with software-based keys and two-factor authentication, requiring both an administrator's and an engineer's keys to lock or unlock data storage devices, and includes a key-based data backup process to prevent data corruption during removal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical access control is used to allow technicians to remove hardware components, then ease of operation is improved, but security and reliability deteriorate as unauthorized personnel can remove components leading to service interruptions and data loss
Solution Approach 1:
The patent replaces mechanical key-based physical access control with an electronic authorization system. The electronic lock mounted on the cabinet door and the electronic locks on individual slots use electronic authentication (keypad entry, card readers, or biometric sensors) instead of physical keys, eliminating the risk of key copying while maintaining ease of access for authorized personnel.
Solution Approach 2:
The patent introduces a controller as an intermediary between the authorization system and the physical locks. The controller receives authentication input, verifies credentials, and controls the electronic locks accordingly. This intermediary layer enables sophisticated authorization logic (such as requiring multiple approvals or time-based access) while keeping the physical interface simple.
2Ease of operation
If physical keys are used for access control, then ease of operation is improved, but security deteriorates as keys can be copied or misused in shared data centers
Solution Approach 1:
The patent eliminates physical keys entirely by replacing them with electronic authentication mechanisms. The system uses keypads, card readers, or biometric sensors to verify authorization, making key copying impossible while maintaining convenient access for authorized personnel through non-contact or minimal-contact authentication methods.
Solution Approach 2:
The patent creates digital copies of authorization credentials (electronic keys stored in the system database) rather than physical copies. Authorized personnel can be granted access rights that are verified electronically, allowing the system to manage multiple authorization levels and revoke access remotely without physical key distribution or retrieval.
3Reliability
If electronic locks with software-based keys and two-factor authentication are implemented, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent implements a multi-functional controller that handles authentication verification, lock control, audit logging, and authorization management in a single device. The electronic lock mechanism serves multiple purposes: securing the cabinet door, securing individual slots, and providing the authentication interface. This consolidation reduces overall system complexity despite the advanced security features.
Solution Approach 2:
The patent combines the authentication system, authorization database, and lock control mechanisms into an integrated security system. The controller merges multiple functions (verification of credentials, decision logic for access grants, communication with locks, and logging) into a single centralized unit, simplifying installation and maintenance while providing robust two-factor authentication and electronic authorization.
Data Source
AI summary
A system and method for securing data storage devices in an information technology (IT) network storage system is provided. The security system comprises a security control computer and electronic locks, which are mounted in a data center cabinet to slots for holding respective data storage devices. The security protocol implemented by the control computer requires an authorized administrator to execute a lock/unlock command identifying a particular device, and to provide a first part of a combination key. Additionally, an on-site hardware engineer is required to input a second part of the key at a terminal on-site at the data center. Upon verification of the first key, and then the second key, the control computer unlocks or locks the appropriate electronic lock. The control computer also implements a data backup/flushing process prior to allowing removal of an online cache board to avoid data corruption, loss, or system interruption.


